天下漏洞,尽知其名
HIGH

CVE-2026-101012 CloudClassroom-PHP-Project SQL注入漏洞

影响攻击者可远程注入SQL,窃取或篡改数据库数据

AI 研判

CloudClassroom-PHP-Project 的 makeresult.php 文件在处理 makeid 参数时未做充分过滤,存在 SQL 注入漏洞。该漏洞可被远程利用,且公开的利用代码已发布,存在被实际攻击的风险。厂商已被告知但未作回应。

影响范围

CloudClassroom-PHP-Project

受影响版本为截至提交 5dadec098bfbbf3300d60c3494db3fb95b66e7be 的代码;由于项目采用滚动发布,暂无具体版本号信息。

漏洞详情

漏洞类型为 SQL 注入。成因是 makeresult.php 对 makeid 参数未进行有效过滤或参数化处理,攻击者可通过构造恶意 SQL 语句拼接进查询。利用方式为远程发送特制请求,从而读取、修改或删除数据库中的敏感数据。

利用条件与风险

利用无需认证,可远程发起,且公开利用代码已存在,实战风险较高。

修复建议

官方暂未发布修复版本,建议对 makeid 参数进行严格过滤或使用参数化查询;临时缓解可限制该接口的访问来源或部署 WAF 拦截恶意请求。

原始情报

A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.